自动测试音频伪造检测器的鲁棒性,找出能骗过检测但不破坏语音质量的攻击链。
Proteus: Automated Adversarial Robustness Testing for Audio Deepfake Detectors
- 用多种日常音频处理组合系统搜索攻击路径。
- 特定处理链可稳定翻转检测结果,且语音清晰度和说话人特征保留完好。
- 发现结果用于针对性重训练,提升检测器抗攻击能力。
我们提出Proteus,一个由Resemble AI开发的自动化鲁棒性测试框架,用于评估音频深度伪造检测系统的可靠性。给定一个检测器,Proteus系统性地搜索一系列日常音频变换(编解码转换、加性噪声、混响、动态范围压缩及VoIP模拟)的组合,以找到能欺骗检测器同时保持语音质量的攻击路径。我们提出了两种互补的搜索策略:(1) 广度优先搜索,全面映射参数空间中各类增强的有效性;(2) 基于Q-learning的智能代理,利用广度优先搜索数据中的结构模式,高效发现更深层的攻击链。在持续部署中对生产级检测器进行测试后发现,特定的增强链可稳定改变检测判断结果,同时保持语音可懂性和说话人身份不变。这些发现被用于指导检测器的针对性再训练,从而提升其鲁棒性。
原文摘要 · Abstract (English)
We present Proteus, a framework developed at Resemble AI for automated robustness testing of our audio deepfake detection system. Given a detector, Proteus systematically searches over sequences of everyday audio transformations (codec transcoding, additive noise, reverberation, dynamic-range compression, and VoIP simulation) to find combinations that fool the detector while preserving speech quality. We propose two complementary search strategies: (1) a breadth-first search that exhaustively maps augmentation effectiveness across the parameter space, and (2) a Q-learning agent designed to efficiently discover deeper attack chains by exploiting structural patterns in the BFS data. We report findings from continuous deployment of Proteus against our production detector, showing that specific augmentation chains can reliably flip detection verdicts while preserving speech intelligibility and speaker identity. We discuss how these findings are used to harden the detector through targeted retraining.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。